<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Ping Issues between ASA and Router NAT in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ping-issues-between-asa-and-router-nat/m-p/5276433#M1120357</link>
    <description>&lt;P&gt;Can You share topolgy? I see two routers and one asa.&lt;/P&gt;
&lt;P&gt;Also can you more elaborate about ospf ypu use' I see static and ospf&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
    <pubDate>Sun, 30 Mar 2025 00:06:19 GMT</pubDate>
    <dc:creator>MHM Cisco World</dc:creator>
    <dc:date>2025-03-30T00:06:19Z</dc:date>
    <item>
      <title>Ping Issues between ASA and Router NAT</title>
      <link>https://community.cisco.com/t5/network-security/ping-issues-between-asa-and-router-nat/m-p/5276432#M1120356</link>
      <description>&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;Ping Issues between ASA and Router - Access-list 99 Impact (Access-list 101 not the issue)&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Problem Description:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;I'm experiencing ping connectivity issues between two networks: 192.168.110.0/25 (behind an ASA firewall) and 172.16.20.0/24 (behind a Cisco router - T-R1).&lt;/P&gt;&lt;P&gt;Initially, the T-R1 router had NAT configured, and an access-list 99 (permit 172.16.20.0 0.0.0.255) was in place. Pings from the 192.168.110.0/25 network were not successful.&lt;/P&gt;&lt;P&gt;After removing the NAT configuration from the T-R1 router, I found that removing the access-list 99 resolved the ping issue. So it seems that the access-list 99 was the culprit.&lt;/P&gt;&lt;P&gt;I also have an access-list 101 on the T-R1 router, but I don't believe this is causing the issue, as pings work fine once access-list 99 is removed.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;ASA Version 9.6(1)&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;hostname GYASA&lt;/P&gt;&lt;P&gt;names&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet1/1&lt;/P&gt;&lt;P&gt;nameif belso1&lt;/P&gt;&lt;P&gt;security-level 100&lt;/P&gt;&lt;P&gt;ip address 192.168.110.1 255.255.255.128&lt;/P&gt;&lt;P&gt;ipv6 address 2001:CB10:110::1/64&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet1/2&lt;/P&gt;&lt;P&gt;nameif belso2&lt;/P&gt;&lt;P&gt;security-level 100&lt;/P&gt;&lt;P&gt;ip address 192.168.120.1 255.255.255.128&lt;/P&gt;&lt;P&gt;ipv6 address 2001:CB20:120::1/64&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet1/3&lt;/P&gt;&lt;P&gt;nameif kulso&lt;/P&gt;&lt;P&gt;security-level 0&lt;/P&gt;&lt;P&gt;ip address 10.0.0.34 255.255.255.252&lt;/P&gt;&lt;P&gt;ipv6 address 2001:CB1:50::2/64&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet1/4&lt;/P&gt;&lt;P&gt;no nameif&lt;/P&gt;&lt;P&gt;no security-level&lt;/P&gt;&lt;P&gt;no ip address&lt;/P&gt;&lt;P&gt;shutdown&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet1/5&lt;/P&gt;&lt;P&gt;no nameif&lt;/P&gt;&lt;P&gt;no security-level&lt;/P&gt;&lt;P&gt;no ip address&lt;/P&gt;&lt;P&gt;shutdown&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet1/6&lt;/P&gt;&lt;P&gt;no nameif&lt;/P&gt;&lt;P&gt;no security-level&lt;/P&gt;&lt;P&gt;no ip address&lt;/P&gt;&lt;P&gt;shutdown&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet1/7&lt;/P&gt;&lt;P&gt;no nameif&lt;/P&gt;&lt;P&gt;no security-level&lt;/P&gt;&lt;P&gt;no ip address&lt;/P&gt;&lt;P&gt;shutdown&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet1/8&lt;/P&gt;&lt;P&gt;no nameif&lt;/P&gt;&lt;P&gt;no security-level&lt;/P&gt;&lt;P&gt;no ip address&lt;/P&gt;&lt;P&gt;shutdown&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Management1/1&lt;/P&gt;&lt;P&gt;management-only&lt;/P&gt;&lt;P&gt;no nameif&lt;/P&gt;&lt;P&gt;no security-level&lt;/P&gt;&lt;P&gt;no ip address&lt;/P&gt;&lt;P&gt;shutdown&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;object network belsohalo1&lt;/P&gt;&lt;P&gt;subnet 192.168.110.0 255.255.255.128&lt;/P&gt;&lt;P&gt;nat (belso1,kulso) dynamic interface&lt;/P&gt;&lt;P&gt;object network belsohalo2&lt;/P&gt;&lt;P&gt;subnet 192.168.120.0 255.255.255.128&lt;/P&gt;&lt;P&gt;nat (belso2,kulso) dynamic interface&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;route kulso 0.0.0.0 0.0.0.0 10.0.0.33 1&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;access-list inside_to_internet extended permit tcp any any&lt;/P&gt;&lt;P&gt;access-list inside_to_internet extended permit icmp any any&lt;/P&gt;&lt;P&gt;access-list KIVULROL_BE extended deny ip any 192.168.110.0 255.255.255.0&lt;/P&gt;&lt;P&gt;access-list KIVULROL_BE extended deny ip any 192.168.120.0 255.255.255.0&lt;/P&gt;&lt;P&gt;access-list KIVULROL_BE extended deny ip any any&lt;/P&gt;&lt;P&gt;access-list KIVULROL_BE extended permit tcp any any eq www&lt;/P&gt;&lt;P&gt;access-list KIVULROL_BE extended permit tcp any any eq 443&lt;/P&gt;&lt;P&gt;access-list KIVULROL_BE extended permit tcp any any eq 1883&lt;/P&gt;&lt;P&gt;access-list KIVULROL_BE extended permit tcp any any eq 8883&lt;/P&gt;&lt;P&gt;access-list KIVULROL_BE extended deny tcp any any eq telnet&lt;/P&gt;&lt;P&gt;access-list KIVULROL_BE extended deny tcp any any eq ftp&lt;/P&gt;&lt;P&gt;access-list KIVULROL_BE extended deny icmp any any&lt;/P&gt;&lt;P&gt;access-list KIVULROL_BE extended permit icmp any any echo&lt;/P&gt;&lt;P&gt;access-list KIVULROL_BE extended permit ip any any&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;access-group inside_to_internet in interface kulso&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;class-map inspection_default&lt;/P&gt;&lt;P&gt;match default-inspection-traffic&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;policy-map type inspect dns preset_dns_map&lt;/P&gt;&lt;P&gt;parameters&lt;/P&gt;&lt;P&gt;message-length maximum 512&lt;/P&gt;&lt;P&gt;policy-map global_policy&lt;/P&gt;&lt;P&gt;class inspection_default&lt;/P&gt;&lt;P&gt;inspect dns preset_dns_map&lt;/P&gt;&lt;P&gt;inspect ftp&lt;/P&gt;&lt;P&gt;inspect tftp&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;service-policy global_policy global&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;telnet timeout 5&lt;/P&gt;&lt;P&gt;ssh timeout 5&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;dhcpd address 192.168.110.10-192.168.110.50 belso1&lt;/P&gt;&lt;P&gt;dhcpd dns 192.168.40.10 interface belso1&lt;/P&gt;&lt;P&gt;dhcpd enable belso1&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;dhcpd address 192.168.120.10-192.168.120.50 belso2&lt;/P&gt;&lt;P&gt;dhcpd dns 192.168.40.10 interface belso2&lt;/P&gt;&lt;P&gt;dhcpd enable belso2&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;router ospf 10&lt;/P&gt;&lt;P&gt;log-adjacency-changes&lt;/P&gt;&lt;P&gt;network 192.168.110.0 255.255.255.128 area 110&lt;/P&gt;&lt;P&gt;network 192.168.120.0 255.255.255.128 area 120&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Current configuration : 1580 bytes&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;version 15.1&lt;/P&gt;&lt;P&gt;no service timestamps log datetime msec&lt;/P&gt;&lt;P&gt;no service timestamps debug datetime msec&lt;/P&gt;&lt;P&gt;no service password-encryption&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;hostname Cloud&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;no ip cef&lt;/P&gt;&lt;P&gt;no ipv6 cef&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;license udi pid CISCO2911/K9 sn FTX1524GKA5-&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;spanning-tree mode pvst&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/0&lt;/P&gt;&lt;P&gt;ip address 10.0.0.25 255.255.255.252&lt;/P&gt;&lt;P&gt;duplex auto&lt;/P&gt;&lt;P&gt;speed auto&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/1&lt;/P&gt;&lt;P&gt;ip address 10.0.0.33 255.255.255.252&lt;/P&gt;&lt;P&gt;duplex auto&lt;/P&gt;&lt;P&gt;speed auto&lt;/P&gt;&lt;P&gt;ipv6 address 2001:CB1:50::1/64&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/2&lt;/P&gt;&lt;P&gt;no ip address&lt;/P&gt;&lt;P&gt;duplex auto&lt;/P&gt;&lt;P&gt;speed auto&lt;/P&gt;&lt;P&gt;shutdown&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/0/0&lt;/P&gt;&lt;P&gt;ip address 10.0.0.6 255.255.255.252&lt;/P&gt;&lt;P&gt;ipv6 address 2001:CB1:10::1/64&lt;/P&gt;&lt;P&gt;ipv6 enable&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/1/0&lt;/P&gt;&lt;P&gt;ip address 10.0.0.10 255.255.255.252&lt;/P&gt;&lt;P&gt;ipv6 address 2001:CB1:40::1/64&lt;/P&gt;&lt;P&gt;ipv6 enable&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/2/0&lt;/P&gt;&lt;P&gt;ip address 10.0.0.2 255.255.255.252&lt;/P&gt;&lt;P&gt;ipv6 address 2001:CB1:30::1/64&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/3/0&lt;/P&gt;&lt;P&gt;no ip address&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan1&lt;/P&gt;&lt;P&gt;no ip address&lt;/P&gt;&lt;P&gt;shutdown&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;router ospf 10&lt;/P&gt;&lt;P&gt;router-id 20.20.20.20&lt;/P&gt;&lt;P&gt;log-adjacency-changes&lt;/P&gt;&lt;P&gt;redistribute static subnets&lt;/P&gt;&lt;P&gt;passive-interface GigabitEthernet0/0&lt;/P&gt;&lt;P&gt;network 10.0.0.4 0.0.0.3 area 0&lt;/P&gt;&lt;P&gt;network 10.0.0.0 0.0.0.3 area 0&lt;/P&gt;&lt;P&gt;network 10.0.0.8 0.0.0.3 area 0&lt;/P&gt;&lt;P&gt;network 10.0.0.24 0.0.0.3 area 0&lt;/P&gt;&lt;P&gt;network 10.0.0.32 0.0.0.3 area 0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip classless&lt;/P&gt;&lt;P&gt;ip route 192.168.100.0 255.255.255.0 GigabitEthernet0/0&lt;/P&gt;&lt;P&gt;ip route 209.100.1.0 255.255.255.0 10.0.0.9&lt;/P&gt;&lt;P&gt;ip route 192.168.110.0 255.255.255.128 10.0.0.34&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip flow-export version 9&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;line con 0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;line aux 0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;line vty 0 4&lt;/P&gt;&lt;P&gt;login&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;end&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;T-R1(config)#do sh run&lt;/P&gt;&lt;P&gt;Building configuration...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Current configuration : 1351 bytes&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;version 15.1&lt;/P&gt;&lt;P&gt;no service timestamps log datetime msec&lt;/P&gt;&lt;P&gt;no service timestamps debug datetime msec&lt;/P&gt;&lt;P&gt;no service password-encryption&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;hostname T-R1&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;no ip cef&lt;/P&gt;&lt;P&gt;ipv6 unicast-routing&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;no ipv6 cef&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;license udi pid CISCO2911/K9 sn FTX1524HHGL-&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;spanning-tree mode pvst&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/0&lt;/P&gt;&lt;P&gt;ip address 10.0.0.21 255.255.255.252&lt;/P&gt;&lt;P&gt;ip nat inside&lt;/P&gt;&lt;P&gt;duplex auto&lt;/P&gt;&lt;P&gt;speed auto&lt;/P&gt;&lt;P&gt;ipv6 address 2001:DB8:2::1/64&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/1&lt;/P&gt;&lt;P&gt;no ip address&lt;/P&gt;&lt;P&gt;duplex auto&lt;/P&gt;&lt;P&gt;speed auto&lt;/P&gt;&lt;P&gt;ipv6 enable&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/2&lt;/P&gt;&lt;P&gt;no ip address&lt;/P&gt;&lt;P&gt;duplex auto&lt;/P&gt;&lt;P&gt;speed auto&lt;/P&gt;&lt;P&gt;shutdown&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/3/0&lt;/P&gt;&lt;P&gt;ip address 10.0.0.9 255.255.255.252&lt;/P&gt;&lt;P&gt;ip access-group 101 in&lt;/P&gt;&lt;P&gt;ip nat outside&lt;/P&gt;&lt;P&gt;ipv6 address 2001:CB1:40::2/64&lt;/P&gt;&lt;P&gt;ipv6 address autoconfig&lt;/P&gt;&lt;P&gt;ipv6 enable&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface Vlan1&lt;/P&gt;&lt;P&gt;no ip address&lt;/P&gt;&lt;P&gt;shutdown&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;router ospf 10&lt;/P&gt;&lt;P&gt;router-id 30.30.30.30&lt;/P&gt;&lt;P&gt;log-adjacency-changes&lt;/P&gt;&lt;P&gt;network 10.0.0.8 0.0.0.3 area 0&lt;/P&gt;&lt;P&gt;network 10.0.0.20 0.0.0.3 area 0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip nat pool Dynamic-tb 201.100.100.1 201.100.100.100 netmask 255.255.255.0&lt;/P&gt;&lt;P&gt;ip nat inside source list 1 pool Dynamic-tb&lt;/P&gt;&lt;P&gt;ip nat inside source static 172.16.10.10 209.100.1.1&lt;/P&gt;&lt;P&gt;ip classless&lt;/P&gt;&lt;P&gt;ip route 192.168.110.0 255.255.255.128 10.0.0.34&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip flow-export version 9&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;access-list 1 permit 172.16.20.0 0.0.0.255&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;line con 0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;line aux 0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;line vty 0 4&lt;/P&gt;&lt;P&gt;login&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;end&lt;/P&gt;</description>
      <pubDate>Sat, 29 Mar 2025 23:50:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ping-issues-between-asa-and-router-nat/m-p/5276432#M1120356</guid>
      <dc:creator>hatvani-balazs-04</dc:creator>
      <dc:date>2025-03-29T23:50:22Z</dc:date>
    </item>
    <item>
      <title>Re: Ping Issues between ASA and Router NAT</title>
      <link>https://community.cisco.com/t5/network-security/ping-issues-between-asa-and-router-nat/m-p/5276433#M1120357</link>
      <description>&lt;P&gt;Can You share topolgy? I see two routers and one asa.&lt;/P&gt;
&lt;P&gt;Also can you more elaborate about ospf ypu use' I see static and ospf&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Sun, 30 Mar 2025 00:06:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ping-issues-between-asa-and-router-nat/m-p/5276433#M1120357</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-03-30T00:06:19Z</dc:date>
    </item>
    <item>
      <title>Re: Ping Issues between ASA and Router NAT</title>
      <link>https://community.cisco.com/t5/network-security/ping-issues-between-asa-and-router-nat/m-p/5276463#M1120360</link>
      <description>&lt;P&gt;Hello!&lt;BR /&gt;&lt;BR /&gt;I uploaded the whole project to Drive so you can download it from here. Thanks in advance!&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;A title="" href="https://drive.google.com/drive/folders/16PYdSicGo5McOCwqVd74oLr_Ax2_djeK?usp=sharing" target="_blank" rel="noopener"&gt;ping issue asa - &amp;gt; router&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 30 Mar 2025 09:13:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ping-issues-between-asa-and-router-nat/m-p/5276463#M1120360</guid>
      <dc:creator>hatvani-balazs-04</dc:creator>
      <dc:date>2025-03-30T09:13:46Z</dc:date>
    </item>
    <item>
      <title>Re: Ping Issues between ASA and Router NAT</title>
      <link>https://community.cisco.com/t5/network-security/ping-issues-between-asa-and-router-nat/m-p/5277146#M1120396</link>
      <description>&lt;P&gt;Here are my thoughts, the ping connectivity issue between 192.168.110.0/25 (ASA) and 172.16.20.0/24 (T-R1) stems from a combination of NAT configuration and access-list conflicts on T-R1. let me break it down.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;NAT Configuration Conflict T-R1 originally had
ip nat inside source list 1 pool Dynamic-tb
access-list 1 permit 172.16.20.0 0.0.0.255&lt;/LI-CODE&gt;&lt;P&gt;This caused source IP translation for traffic originating from 172.16.20.0/24 when exiting T-R1's NAT outside interface. Return traffic to the ASA (from 172.16.20.x) was rewritten with NAT pool IPs (201.100.100.x), which the ASA didn’t recognize as valid responses to original pings.&lt;/P&gt;&lt;P&gt;On the ASA nat configuration&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;The ASA’s belso1 interface uses dynamic PAT
nat (belso1,kulso) dynamic interface&lt;/LI-CODE&gt;&lt;P&gt;Outbound pings from 192.168.110.0/25 were already being translated to the ASA’s kulso&amp;nbsp; interface IP (10.0.0.34). T-R1 additional NAT created a double-NAT scenario breaking the ICMP echo-reply path consistency.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;With NAT enabled, T-R1’s access-list 1 allowed NAT for 172.16.20.0/24 but blocked non-NATted traffic from 192.168.110.0/25 due to implicit deny in NAT rules. After removing NAT and access-list 1, traffic flowed natively via the static route.&lt;/P&gt;&lt;P&gt;ip route 192.168.110.0 255.255.255.128 10.0.0.34&lt;/P&gt;&lt;P&gt;ensuring unmodifed bidirectional communication. Why Access-List 101 Wasn’t the Issue.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Access-list 101 on T-R1’s Gig0/3/0 inbound&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;interface Gig0/3/0
  ip access-group 101 in&lt;/LI-CODE&gt;&lt;P&gt;Only filters incoming traffic to T-R1’s NAT outside interface, not affecting outbound responses to the ASA&lt;/P&gt;&lt;P&gt;Workaround:&lt;/P&gt;&lt;P&gt;Removing NAT eliminated IP translation conflicts.&lt;/P&gt;&lt;P&gt;Removing access-list 1 (misidentified as 99 in the query) stopped unintended filtering of non-NATted traffic&lt;/P&gt;&lt;P&gt;Apply these configuration on the ASA.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;access-list KIVULROL_BE extended permit icmp any any echo
access-list KIVULROL_BE extended permit icmp any any echo-reply&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 01 Apr 2025 11:32:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ping-issues-between-asa-and-router-nat/m-p/5277146#M1120396</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2025-04-01T11:32:52Z</dc:date>
    </item>
    <item>
      <title>Re: Ping Issues between ASA and Router NAT</title>
      <link>https://community.cisco.com/t5/network-security/ping-issues-between-asa-and-router-nat/m-p/5277153#M1120397</link>
      <description>&lt;P&gt;Sorry I can not open PKT file.&lt;/P&gt;
&lt;P&gt;I dont use packet tracer anymore.&lt;/P&gt;
&lt;P&gt;Hope other help you.&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Tue, 01 Apr 2025 12:02:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ping-issues-between-asa-and-router-nat/m-p/5277153#M1120397</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-04-01T12:02:56Z</dc:date>
    </item>
  </channel>
</rss>

